Programmatic Ad Fraud: How to Protect Your Ad Spend

Your programmatic campaign is delivering 2 million impressions per month, your reporting shows strong viewability numbers, and your conversion rate is 0.02%. One of two things is happening: either your creative is wrong, or a meaningful portion of those impressions are not being seen by real people. Before you rebuild your creative, it is worth ruling out the second possibility — because programmatic ad fraud is pervasive enough to explain performance problems that look like strategy problems.

The fraud risk built into programmatic advertising is structural. The automated, high-speed nature of real-time bidding creates opportunities for bad actors at every layer of the supply chain.


The Five Types of Ad Fraud You'Re Most Likely to Encounter

Bot traffic (general invalid traffic / GIVT): Non-human traffic generated by automated scripts that simulate browsing behavior. Bots can click ads, load pages, and trigger impression events without any human involvement. Basic bot traffic is the most common form of invalid traffic and is filtered by most reputable DSPs at the pre-bid stage. The challenge is sophisticated bot traffic (SIVT) that mimics human behavior patterns and evades standard filters.

Domain spoofing: Fraudulent publishers misrepresent their inventory to appear as premium publishers in the auction. Your DSP bids $15 CPM for what appears to be a slot on a respected news site, but the impression actually serves on a low-quality or fake site that spoofed the premium domain. Ads.txt was created specifically to combat this — it is a text file that publishers use to declare which ad tech companies are authorized to sell their inventory.

Ad stacking: Multiple ads are placed on top of each other in a single ad slot. Only the top ad is visible to the user, but all stacked ads register as served and generate billing events. Publishers running this scheme collect revenue for ads that were never seen.

Pixel stuffing: Ads are served in a 1x1 pixel slot, invisible to the human eye but counted as an impression by the ad server. The ad registers as served, the publisher gets paid, and your creative is never actually seen.

Click fraud: Clicks on your display ads are generated by bots or low-wage click farms, driving up your click-through rate and burning CPC budget without any real prospect engagement. Common on performance-based campaigns where publishers earn per click rather than per impression.

Understanding how fraud inflates your effective CPM requires tracking your valid impression rate (total impressions minus invalid traffic) rather than accepting raw impression numbers as accurate.


How Fraudsters Target Programmatic Campaigns

Fraud is concentrated in specific areas of the programmatic ecosystem, and understanding where it clusters helps you avoid it.

Open exchange buying is significantly more fraud-prone than private marketplace (PMP) or direct buying. The open exchange is accessible to virtually any publisher, including fraudulent ones, which means fraud rates are higher in open auction inventory than in curated supply. Running exclusively on open exchange without verification tools is the highest-risk programmatic configuration.

Long-tail inventory networks: Ad networks and exchanges that aggregate inventory from thousands of small publishers are harder to audit. Quality control varies dramatically, and fraudulent sites can operate for weeks before detection.

Mobile in-app inventory: App install fraud, SDK spoofing (fake app events reported to your measurement partner), and ad stacking are endemic to the mobile in-app programmatic market. Invalid traffic rates in mobile in-app programmatic are consistently higher than desktop or CTV.

New DSP seats or supply paths: Fraudsters actively look for supply paths with less fraud scrutiny. If you switch DSPs or add a new exchange, validate the inventory quality before scaling spend.

Targeting precision as a fraud defense is real: narrow, well-defined audience segments naturally exclude the low-quality domains where bot traffic concentrates, because those domains do not have valuable audiences to bid on. Broad targeting on cheap inventory is where fraud is most concentrated.


The Tools That Catch Fraud Before It Drains Your Budget

Ads.txt verification: Publishers publish an ads.txt file on their domain declaring authorized sellers. Before bidding on inventory, a properly configured DSP or pre-bid filter can check whether the selling entity is listed in the publisher's ads.txt file. Buying only from ads.txt-authorized sellers eliminates most domain spoofing.

DoubleVerify (DV): A third-party ad verification platform that applies pre-bid filtering (blocking fraudulent impressions before you pay for them), post-bid measurement, and brand safety enforcement. DoubleVerify integrates directly with most major DSPs. Cost is typically $0.10–$0.20 CPM, applied to verified impressions.

Integral Ad Science (IAS): DoubleVerify's primary competitor, with comparable capabilities for pre-bid fraud filtering, viewability measurement, and brand safety. Some advertisers run both simultaneously to compare rates, but for most startup budgets, one verification vendor is sufficient.

MOAT by Oracle: Primarily a viewability and attention measurement tool. Useful for auditing whether your ads are actually viewable (in-screen for 1+ seconds) rather than purely relying on the DSP's own viewability reporting.

Supply path optimization (SPO): The practice of limiting your DSP buying to specific, vetted supply paths rather than buying across every available exchange. SPO reduces the number of intermediaries between your bid and the publisher, which reduces both fraud risk and markup. Most enterprise DSPs offer SPO controls.

Which DSPs have the strongest fraud controls varies: The Trade Desk's built-in seller verification and pre-bid filtering is among the strongest in the industry. Verify your DSP's fraud controls before assuming they are sufficient on their own.


A Fraud-Prevention Checklist for Startup Campaigns

Use this checklist before launching any programmatic campaign with more than $5,000/month in spend.

Pre-launch checks: - Confirm your DSP uses ads.txt verification to filter unauthorized sellers - Enable all available pre-bid fraud filters in your DSP settings (IVT, domain quality, viewability thresholds) - Add DoubleVerify or IAS to your media plan and budget for the verification CPM - Configure brand safety category exclusions (gambling, adult content, sensationalist news) in your DSP and in your verification tool - Set inventory quality thresholds: minimum 40% viewability rate for display, minimum 70% for video

Campaign structure checks: - Prefer private marketplace (PMP) deals over open exchange for any audience you care about - Apply frequency caps to limit repetitive exposure and reduce bot traffic exposure - Exclude known low-quality domains using your DSP's domain blocklist or a pre-built exclusion list from IAS or DoubleVerify - Set geographic targeting to your actual market — campaigns targeting broad international inventory have significantly higher fraud rates

Ongoing monitoring: - Review domain-level performance weekly — any unknown domain generating high impressions and zero conversions should be investigated and potentially excluded - Monitor invalid traffic rate in your verification tool — above 10% IVT on open exchange is a quality signal worth acting on - Check viewability rate monthly — campaigns below 50% viewability are delivering below industry standards

Asking your agency about fraud protections should be a standard part of any agency evaluation. A legitimate programmatic partner has a clear answer to "what does your fraud prevention stack look like?"


Myth-Busting: What Ad Fraud Prevention Can and Can'T Do

Myth: "My DSP's built-in fraud detection is enough." Most DSPs provide general invalid traffic (GIVT) filtering, which catches obvious bot traffic. Sophisticated invalid traffic (SIVT) — the harder-to-detect fraud — requires an independent verification layer. DSP-only fraud protection misses a significant share of invalid traffic, particularly in programmatic open exchange environments.

Myth: "Private marketplace deals are fraud-free." PMP deals are significantly lower fraud risk than open exchange, but they are not fraud-free. Publishers running PMP deals are more thoroughly vetted, but ad stacking, pixel stuffing, and viewability fraud can still occur. Verification tools should still be active on PMP buys.

Myth: "High viewability scores mean my ads are being seen." Standard viewability (50% of pixels in-screen for 1+ seconds for display) is a low bar. An ad that is technically viewable can still be in a cluttered page position, below the fold on a fast-scrolling page, or auto-loaded in a browser tab the user never focuses on. Viewability compliance and actual human attention are different things.

Myth: "Brand safety tools prevent all reputation risk." Brand safety segments block ads from appearing on categorically unsafe content (adult, violence, extremism). They do not prevent your ad from appearing on low-quality clickbait sites, misinformation pages that do not trigger content categories, or made-for-advertising (MFA) sites designed to generate fraudulent impressions without technically violating brand safety rules.

Myth: "Ad fraud only affects large advertisers." Fraud is distributed across all advertisers buying open exchange inventory. Startup budgets are arguably more vulnerable, not less, because the absolute dollar loss from fraud is more painful relative to total budget, and smaller teams have less bandwidth to audit campaign-level quality signals regularly.


Key Takeaways

  • The five most common programmatic fraud types are bot traffic, domain spoofing, ad stacking, pixel stuffing, and click fraud.
  • Open exchange buying without verification tools is the highest-risk programmatic configuration — add DoubleVerify or IAS before scaling any campaign.
  • Ads.txt verification eliminates most domain spoofing; confirm your DSP enforces it before buying.
  • Private marketplace (PMP) deals carry significantly lower fraud risk than open exchange, with only modest CPM premiums.
  • Supply path optimization (SPO) reduces fraud exposure and intermediary markup simultaneously.
  • DSP-built-in fraud filtering catches general invalid traffic (GIVT) only; sophisticated IVT requires an independent verification layer.

FAQ

How much of my programmatic budget is being lost to fraud? Industry estimates vary widely: the Association of National Advertisers (ANA) has found that 23–35% of programmatic display impressions exhibit some form of invalid traffic, with the open exchange significantly worse than PMP buying. For startup campaigns without verification tools, losing 15–25% of display budget to fraud is a conservative estimate. With verification tools in place, invalid traffic rates typically drop to 3–8%.

Is ad fraud illegal? Some forms of ad fraud are criminally prosecuted — large-scale click fraud operations and bot networks have resulted in federal charges in the US. Domain spoofing violates multiple consumer protection statutes. However, the practical reality is that most small-scale fraud goes undetected and unprosecuted. The industry response has been technical (ads.txt, verification tools) rather than primarily legal.

What is the difference between invalid traffic and ad fraud? Invalid traffic (IVT) is any non-human or otherwise invalid interaction with an ad — it includes accidental clicks, bot crawls, and measurement errors that are not necessarily intentional fraud. Ad fraud specifically involves intentional deception to generate revenue. IVT includes fraud but is a broader category. Verification vendors report IVT rates; not all IVT represents deliberate fraud, but all of it wastes budget.

Should I stop buying open exchange entirely? Not necessarily — but you should not buy open exchange without verification tools and domain-level reporting. Open exchange provides scale and reach that private marketplace alone cannot match. The approach is to buy open exchange selectively, with verification protection, domain exclusion lists, and regular quality audits, rather than to avoid it entirely.